vendor:
MySQL
by:
Stefano Di Paola
7.5
CVSS
HIGH
Local/Remote Privileges Escalation - input validation
20
CWE
Product Name: MySQL
Affected Version From: MySQL 4.0.23
Affected Version To: MySQL 4.1.10
Patch Exists: YES
Related CWE: N/A
CPE: a:mysql:mysql
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Mandrake 10.1 /Debian Sarge
2005
MySQL CREATE FUNCTION func table arbitrary library injection
MySQL is reported prone to multiple vulnerabilities that can be exploited by a remote authenticated attacker. The following individual issues are reported: Insecure temporary file-creation vulnerability, Input-validation vulnerability, Remote arbitrary-code execution vulnerability. These issues are reported to exist in MySQL versions prior to MySQL 4.0.24 and 4.1.10a.
Mitigation:
Upgrade to the latest version of MySQL